EDBT 2026 Demo / reviewers in the wild / expert
Fabricio Ceschin
dblp:235/8319 · also Fabrício Ceschin
· DBLP profile ↗
7ranked-venue papers
1as first author
5since 2021 · last 2025
0000-0001-6853-8083ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 3 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021Computer networks · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | One Video to Steal Them All: 3D-Printing IP Theft through Optical Side-ChannelsabstractThe 3D printing industry is rapidly growing and increasingly adopted across various sectors, including manufacturing, healthcare, and defense. However, the operational setup often involves hazardous environments, necessitating remote monitoring through cameras and other sensors, which opens the door to cyber-based attacks. In this paper, we show that an adversary with access to video recordings of the 3D printing process can reverse-engineer the underlying 3D print instructions. Our model tracks the printer nozzle's movements during the printing process and maps the corresponding trajectory into G-code instructions. Further, it identifies the correct parameters, such as feed rate and extrusion rate, leading us to be able to successfully perform IP theft. To validate the success of IP theft, we design an equivalence checker that quantitatively compares two sets of 3D print instructions, evaluating their similarity in producing objects that are alike in shape, external appearance, and internal structure. Our equivalence checker, unlike other simple distance-based metrics such as normalized mean square error, is rotational as well as translational invariant. This is necessary to capture shifts in the base/start position of the reverse-engineered instructions relative to the actual 3D print instructions that can happen due to different camera positions. Our model achieves an average accuracy of 90.87% and generates 30.20% fewer instructions compared to the current state-of-the-art methods that produce instructions that either lead to faulty or incorrect (in terms of difference in shape and internal structure) 3D prints. Additionally, we use our model to reverse-engineer the 3D print instructions from a video recording and print a fully-functional counterfeit object. Twisha Chattopadhyay, Fabricio Ceschin, Marco E. Garza, Dymytriy Zyunkin, Animesh Chhotaray, Aaron P. Stebner, Saman A. Zonouz, Raheem A. Beyah |
CCS | 2 |
| 2023 | Fast & Furious: On the modelling of malware detection as an evolving data streamabstractMalware is a major threat to computer systems and imposes many challenges to cyber security. Targeted threats, such as ransomware, cause millions of dollars in losses every year. The constant increase of malware infections has been motivating popular antiviruses (AVs) to develop dedicated detection strategies, which include meticulously crafted machine learning (ML) pipelines. However, malware developers unceasingly change their samples' features to bypass detection. This constant evolution of malware samples causes changes to the data distribution (i.e., concept drifts) that directly affect ML model detection rates, something not considered in the majority of the literature work. In this work, we evaluate the impact of concept drift on malware classifiers for two Android datasets: DREBIN (about 130K apps) and a subset of AndroZoo (about 285K apps). We used these datasets to train an Adaptive Random Forest (ARF) classifier, as well as a Stochastic Gradient Descent (SGD) classifier. We also ordered all datasets samples using their VirusTotal submission timestamp and then extracted features from their textual attributes using two algorithms (Word2Vec and TF-IDF). Then, we conducted experiments comparing both feature extractors, classifiers, as well as four drift detectors (DDM, EDDM, ADWIN, and KSWIN) to determine the best approach for real environments. Finally, we compare some possible approaches to mitigate concept drift and propose a novel data stream pipeline that updates both the classifier and the feature extractor. To do so, we conducted a longitudinal evaluation by (i) classifying malware samples collected over nine years (2009-2018), (ii) reviewing concept drift detection algorithms to attest its pervasiveness, (iii) comparing distinct ML approaches to mitigate the issue, and (iv) proposing an ML data stream pipeline that outperformed literature approaches. Fabricio Ceschin, Marcus Botacin, Heitor Murilo Gomes, Felipe Azevedo Pinage, Luiz Eduardo Soares de Oliveira, André Ricardo Abed Grégio |
Expert Syst. Appl. | 1 |
| 2022 | AntiViruses under the microscope: A hands-on perspective
Marcus Botacin, Felipe Duarte Domingues, Fabricio Ceschin, Raphael Machnicki, Marco A. Z. Alves, Paulo Lício de Geus, André Ricardo Abed Grégio |
Comput. Secur. | 3 |
| 2021 | Taking a Peek: An Evaluation of Anomaly Detection Using System calls for ContainersabstractThe growth in the use of virtualization in the last ten years has contributed to the improvement of this technology. The practice of implementing and managing this type of isolated environment raises doubts about the security of such systems. Considering the host's proximity to a container, approaches that use anomaly detection systems attempt to monitor and detect unexpected behavior. Our work aims to use system calls to identify threats within a container environment, using machine learning based strategies to distinguish between expected and unexpected behaviors (possible threats). Gabriel R. Castanhel, Tiago Heinrich, Fabricio Ceschin, Carlos Maziero |
ISCC | 3 |
| 2021 | Challenges and pitfalls in malware research
Marcus Botacin, Fabricio Ceschin, Ruimin Sun, Daniela Oliveira 0001, André Ricardo Abed Grégio |
Comput. Secur. | 2 |
| 2020 | We need to talk about antiviruses: challenges & pitfalls of AV evaluations
Marcus Botacin, Fabricio Ceschin, Paulo Lício de Geus, André Ricardo Abed Grégio |
Comput. Secur. | 2 |
| 2019 | L(a)ying in (Test)Bed - How Biased Datasets Produce Impractical Results for Actual Malware Families' Classification
Tamy Beppler, Marcus Botacin, Fabricio Ceschin, Luiz Eduardo Soares de Oliveira, André Ricardo Abed Grégio |
ISC | 3 |